Policy Management Engine for Microsegmented Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security policies in microsegmented networks are difficult to manage, as they are directly configured on endpoint devices, making it challenging to detect and prevent unauthorized modifications, which can lead to insider threats and security breaches.

Innovation Solution

A policy management engine and processor system that detects, identifies, and automatically corrects modifications to security policies across multiple resources, notifying administrators of any changes and providing detailed information for analysis and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security policies are directly configured on endpoint devices to enable microsegmentation, then network security control is improved, but vulnerability to unauthorized modifications increases

Engineering Contradiction:
Improvenetwork security controlVSAvoidunauthorized modifications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a policy management engine as an intermediary between administrators and endpoint devices. This engine continuously monitors security policies on endpoint devices, detects unauthorized modifications, and automatically restores legitimate policies, thereby resolving the contradiction between maintaining security control and preventing unauthorized changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous monitoring and feedback mechanisms where the policy management engine regularly checks security policies on endpoint devices, compares them against authorized configurations, and automatically corrects deviations. This closed-loop feedback system ensures security control while preventing the persistence of unauthorized modifications.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If security policies are configured on distributed firewalls to allow user access, then ease of operation is improved, but risk of malicious modifications increases

Engineering Contradiction:
Improveuser access controlVSAvoidmalicious software modifications
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The policy management engine serves as a protective intermediary that monitors security policies on distributed firewalls and endpoint devices. It detects modifications made by malicious software and automatically restores authorized policies, allowing user access operations while preventing malicious modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service capabilities where the policy management engine automatically detects and corrects unauthorized modifications without requiring manual administrator intervention. This automated self-correction mechanism maintains ease of operation while defending against malicious software.

Inventive Principle:
Principle #25Self-service

3Difficulty of detecting and measuring

If comprehensive monitoring of security policies is implemented, then detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvemodification detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The policy management engine implements self-service monitoring by automatically continuously checking security policies on endpoint devices and distributed firewalls. It autonomously detects modifications, determines their legitimacy, and initiates correction actions without requiring complex external monitoring infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system combines multiple functions including policy monitoring, modification detection, legitimacy determination, and automatic correction into a single integrated policy management engine. This merging of functions simplifies the overall system architecture while maintaining comprehensive detection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11303678B2Determination and autocorrection of modified security policies
Publication Date: 2022.04.12 COLORTOKENS INC
  • US11303678B2 patent drawing
  • US11303678B2 patent drawing
  • US11303678B2 patent drawing

AI summary

A method and a system for automatically managing security policies at multiple resources are provided. A policy management engine receives and deploys a security policy configured for each resource with one or more configuration parameters on a security component of each resource. The policy management engine determines modifications made to the security policy at a corresponding resource and automatically corrects the security policy at the corresponding resource. The policy management engine generates and renders a notification including the security policy, the modifications, and detailed information of the modifications and the automatic correction of the security policy to an administrator device. The detailed information includes a description, a type, a timestamp, number of instances, etc., of each modification, volume and type of traffic flow incurred due to the modifications, historical modification information, a timestamp and a status of the automatic correction, historical correction information, a resource identification, event information, etc.